Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 | 001.exe Detection Name: W32.9F1F11A708-100.SBX.TG** SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 MD5: 61e046145ee5cf45aeb033cd71e8b07c Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 14d ago |
| sha256 | 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 | sample.exe Detection Name: W32.C4DD71E347-95.SBX.TG SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 MD5: 41444d7018601b599beac0c60ed1bf83 Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 14d ago |
| sha256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | content.js Detection Name: W32.38D053135D-95.SBX.TG SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 14d ago |
| sha256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | lware files from Talos telemetry over the past week SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 14d ago |
| sha256 | a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 | tGuard.exe Detection Name: W32.228C316455-95.SBX.TG SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 14d ago |
| sha256 | c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 | .exe Detection Name: Win.Dropper.Miner::95.sbx.tg** SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 MD5: 9a47c4d379998ade2f8f99e23a630c06 Talos Rep: https://ta | The story behind the intelligence Cisco Talos | · 14d ago |
| domain | acemlnd.com | ssage body to route through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicks | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | acems10.com | aped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5% of messages matche | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | activehosted.com | e through its own click-tracking domains (acemlnd[.]com and activehosted[.]com), so the URLs the recipient clicks do not point at the br | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | advancefundingboost.com | usinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefundi | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | catalystboostfunding.com | rbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapi | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | catalystcapitalharbor.com | tcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | digitalcapitalboost.com | omain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | digitalrushcapital.com | tcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[ | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | directcapitalboost.com | radvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalha | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | directcapitalpulse.com | uardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalru | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | elevatecapitalrush.com | capitalpulse[.]com 19,767 catalystboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20 | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | emsd4.com | ending pool , shaped acems<N>[.]com and emsd<N>[.]com (e.g. emsd4[.]com, s9.acems10[.]com). Across the measured activity, ~98.5% | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | fundingexpresscapital.com | stboostfunding[.]com 19,519 elevatecapitalrush[.]com 19,395 fundingexpresscapital[.]com 18,695 Table 1. Top 20 (by signature hits) of the 148 fin | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardiancapitalway.com | ourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwav | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardiangrowthfunding.com | and the per-domain volume: Sender domain Hits (Feb 9, 2026) guardiangrowthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanex | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardianloccapital.com | etboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.] | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | guardianlocchoice.com | talrushcapital[.]com 20,796 guardianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[. | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | harboradvancefunding.com | cefundingboost[.]com 24,053 guardiancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[ | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | onlinedirectfinance.com | tedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfund | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | ourbusinessloans.com | rdianloccapital[.]com 20,781 guardianlocchoice[.]com 20,553 ourbusinessloans[.]com 20,444 directcapitalpulse[.]com 19,767 catalystboostfundi | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | rocketboostfunding.com | rectfinance[.]com 21,195 catalystcapitalharbor[.]com 21,130 rocketboostfunding[.]com 20,908 digitalrushcapital[.]com 20,796 guardianloccapital | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | thebusinessloanexpress.com | growthfunding[.]com 30,442 digitalcapitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.] | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | unitedfundingwave.com | ancapitalway[.]com 23,921 harboradvancefunding[.]com 23,595 unitedfundingwave[.]com 23,269 directcapitalboost[.]com 22,875 onlinedirectfinanc | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | yourlocfunding.com | pitalboost[.]com 27,021 thebusinessloanexpress[.]com 25,048 yourlocfunding[.]com 24,482 advancefundingboost[.]com 24,053 guardiancapitalwa | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| url | https://<account-id>.acemlnd[ | s do not point at the brand domain at all – they look like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehoste | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| url | https://<brand-subdomain>.activehosted[ | k like: hxxps://<account-id>.acemlnd[.]com/<tracking-token> hxxps://<brand-subdomain>.activehosted[.]com/<tracking-token> Most of the flagged messages carried | ASCII smuggling crosses over from AI prompt injection to phishing evasion Microsoft Security Blog | · 14d ago |
| domain | caixaentradas1inboxshop.site | ft Edge and is downloaded from a distribution domain named "caixaentradas1inboxshop[.]site." An analysis of the files associated with the domain has | BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory The Hacker News | · 14d ago |
| domain | infect.online | tion for the Infected Marketplace (aka "Banco de Infects," "infect[.]online"), a platform where the threat actor monetizes initial ac | BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory The Hacker News | · 14d ago |
| domain | draw.io | sers and security tools to utilities such as Baidu Netdisk, draw.io, and Sejda PDF, to trick users into downloading malicious i | Counterfeit installers turn routine software downloads into enterprise breaches CSO Online | · 14d ago |
| domain | nodejs.org | y, attackers downloaded the official Node.js installer from nodejs[.]org and used the trusted, signed runtime to deploy a maliciou | Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks The Hacker News | · 14d ago |
| domain | duckdns.org | Let's Encrypt TLS certificate using the domain m-doxa-apodo.duckdns[.]org and following a unique dynamic DNS naming standard. Share | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| sha256 | 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c | 648aa4e0425b83c0e863a8fee5 5 178.128.87[.]160 June 19, 2026 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c 5 178.128.87[.]160 Table 2. Certificate procurement timelin | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| sha256 | 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 | 23187010c4d38dbf88fcb40bf8 1 165.22.184[.]26 April 20, 2026 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 5 178.128.87[.]160 June 19, 2026 46ac289ce0c13666de616446f5 | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| sha256 | 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 | ture. Date Certificate SHA-256 Hash SANs Host Feb. 27, 2026 7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 1 165.22.184[.]26 April 20, 2026 4e218e70afdbb116209ec0ebe8 | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| sha256 | 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec | cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additiona | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| sha256 | a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 | 65.22.184[.]26 Brazilian Financial Campaign SHA-256 hashes: a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| url | http://167.148.195[ | a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec URL: hxxp[:]//167.148.195[.]53:8888/socktz_v9.exe Additional Resources Operation Esc | Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Palo Alto Unit 42 | · 14d ago |
| domain | anondns.net | nnected back to an attacker-controlled domain ( borertors92.anondns[.]net ). While the attack chain here also involved the ScreenCo | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| domain | opik.net | l, this IP address was associated with the domain tele-sync.opik[.]net during the month of August. Figure 3: According to VirusT | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| sha256 | 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020 | s. 7a4d7d66502d4260 Malicious ScreenConnect ID 1.vbs SHA256 08bc4e82883eb42fc5219b206555b7a02a879860c76b4a12b2f82a64f6cc9020 VBScript file executed through wscript.exe . 2.vbs SHA256 d | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| sha256 | 110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66 | 0 VBScript file executed through wscript.exe . 3.vbs SHA256 110fffc85370bb7cc60fa023447165c7e99175473d76bc5ffb2abecaa3a41d66 VBScript file executed through wscript.exe . 4.vbs SHA256 d | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| sha256 | 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260 | 836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117f3260 VBScript file executed through wscript.exe . 3.vbs SHA256 1 | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| sha256 | de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 | 0 VBScript file executed through wscript.exe . 2.vbs SHA256 de3b6836a88ae4b117e3b6de0e9cce3cd56a2b27b462d69e50c2fcac4089a457 19a3534da9f60c726be426ec5cc2b72c2d1254fefa0782bd2f08ef08117 | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| sha256 | de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede | 6 VBScript file executed through wscript.exe . 4.vbs SHA256 de89d560fc8302c778d88e3938327b240fa0db9a64fc1d5643067eedcbd2aede VBScript file executed through wscript.exe . Trojan:Script/ | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| sha256 | ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de | Defender Detection for 4.vbs WindowsServiceHost.vbs SHA256 ffd6d23f579571cc61936145791975da78b6ae914d780a9447a8f53c3688a0de VBScript file executed through wscript.exe . WindowsService | Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity Huntress | · 14d ago |
| ipv4 | 162.55.0.0 | an Hetzner’s normal announcement of the surrounding block ( 162.55.0.0/16 ), so under standard BGP route selection it took precede | Security Incident – BGP Hijacking Lobsters · security | · 14d ago |
| ipv4 | 162.55.80.0 | TC , a block of IP addresses used by Softaculous services ( 162.55.80.0/24 , part of our infrastructure at Hetzner) was affected by | Security Incident – BGP Hijacking Lobsters · security | · 14d ago |
| md5 | 2ec37a7cc8daf20b10e1ad6221061ca5 | the malicious actor’s secure shell client hash fingerprint: 2ec37a7cc8daf20b10e1ad6221061ca5 showing an established session. Attempt number 6 shows a fa | Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd) SANS Internet Storm Center | · 14d ago |
| domain | app-microsoft-edge.com.cn | .]com." Some of the counterfeit websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | baidu-pan.com.cn | t websites are listed below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | calibre-ebook.com.cn | below - app-microsoft-edge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | cn-drawio.com.cn | ge[.]com[.]cn baidu-pan[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | gehie246.com | lure content to trigger the download of a ZIP archive from "gehie246[.]com." Some of the counterfeit websites are listed below - app | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | gw-sogou.com.cn | an[.]com[.]cn calibre-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[. | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | iualef.net | and 28300. Two C2 domains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of th | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | kaspersky-lab.hl.cn | e-ebook[.]com[.]cn cn-drawio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[. | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | mindmoster.com.cn | awio[.]com[.]cn gw-sogou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[. | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | ocam-pc.com.cn | ou[.]com[.]cn kaspersky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[ | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | oijfwe.net | omains associated with the activity are "iualef[.]net" and "oijfwe[.]net." It's unclear what the end goal of the campaign is, as M | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | pc-razerzone.com.cn | rsky-lab[.]hl[.]cn mindmoster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-you | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | sejda.hl.cn | oster[.]com[.]cn ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | steelseries-cn.com.cn | ocam-pc[.]com[.]cn pc-razerzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | translate-youdao.hl.cn | erzone[.]com[.]cn sejda[.]hl[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelit | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | zh-diskgenius.com.cn | l[.]cn steelseries-cn[.]com[.]cn translate-youdao[.]hl[.]cn zh-diskgenius[.]com[.]cn The web pages are high-fidelity clones of the legitimat | Fake Software Installers Disable Windows Update and Weaken Microsoft Defender The Hacker News | · 15d ago |
| domain | gov.br | t it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages | Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages The Hacker News | · 15d ago |
| domain | hunt.io | reverse-proxy technique on IIS servers in September 2025 . Hunt.io said in July 2025 that it had found more than 630,000 URLs | Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages The Hacker News | · 15d ago |
| domain | registro.br | thorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whether | Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages The Hacker News | · 15d ago |
| domain | cdn.nerat.cc | le - /usr/local/virtualizor/zzvirtservice Injected string - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| domain | connect.ne-rat.xyz | g - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat[.]xyz Injected string - jre-runtime.dat Command-and-control ( | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| ipv4 | 3.2.9.9 | anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (Releas | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| sha256 | 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 | n the official scanner , whose retrieved-script SHA-256 was 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 when checked on September 2, 2026. Contact support before r | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| sha256 | b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7 | oad - /usr/lib/jvm/.cache/jre-runtime.dat Payload SHA-256 - b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7 Marker file - /usr/lib/jvm/.cache/.installed Marker file - | BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access The Hacker News | · 15d ago |
| domain | advancedplacyncement.vu | .51[.]x) and 104.37.188[.]94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunio | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | amstardmzsmc.vu | 94 Observed replay infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalf | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | arandasoftzfdware.vu | infrastructure advancedplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]v | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | avisoretentiunionllc.vu | dplacyncement[.]vu amstardmzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]v | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | capitalflwxinancialpartners.vu | mzsmc[.]vu arandasoftzfdware[.]vu avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcea | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | certififiycationedge.vu | avisoretentiunionllc[.]vu capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafww | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | connectivnqzityltd.vu | capitalflwxinancialpartners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu excelte | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | crrbcearegroup.vu | ners[.]vu certififiycationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolution | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | digitaltrafwwrficsystems.vu | cationedge[.]vu connectivnqzityltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[. | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | exceltecbusinessbwpsolutions.vu | yltd[.]vu crrbcearegroup[.]vu digitaltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmi | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | genamewwgdiamarketing.vu | taltrafwwrficsystems[.]vu exceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]v | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | globaieflsoftinc.vu | xceltecbusinessbwpsolutions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | globalmixeucbdmodetechnologyinc.vu | tions[.]vu genamewwgdiamarketing[.]vu globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeul | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | globalprojectspvtltd.vu | globaieflsoftinc[.]vu globalmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufactu | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | idoej.com | l panel host found by pivoting from the phishing page title idoej[.]com Domain of the phishing control panel host found via rever | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | joinbusinessmanagementconsdjeulting.vu | balmixeucbdmodetechnologyinc[.]vu globalprojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[ | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | kentmanqhfufacturingcompany.vu | rojectspvtltd[.]vu joinbusinessmanagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu mon | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | kleepxrnlinecorporation.vu | nagementconsdjeulting[.]vu kentmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprorm | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | knsinternacshtional.vu | ntmanqhfufacturingcompany[.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestate | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | monday.com | k the true destination by using an open direct parameter on Monday[.]com's tracking service. When clicked the link routes the vict | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | monttmmlrustcompany.vu | [.]vu kleepxrnlinecorporation[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[ | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
| domain | mtprormtductions.vu | tion[.]vu knsinternacshtional[.]vu monttmmlrustcompany[.]vu mtprormtductions[.]vu realestatecotblrp[.]vu siottxgroup[.]vu summitcapitaltrap | Inside Knight Office, a New M365 AiTM Phishing Kit Huntress | · 15d ago |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.